CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13648  CVE-2005-2442  Candidate  Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.  Assigned (20050803)  None (candidate not yet proposed)    View
13649  CVE-2005-2443  Candidate  Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.  Assigned (20050803)  None (candidate not yet proposed)    View
13650  CVE-2005-2444  Candidate  Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.  Assigned (20050803)  None (candidate not yet proposed)    View
13651  CVE-2005-2445  Candidate  SQL injection vulnerability in viewPrd.asp in Product Cart 2.6 allows remote attackers to execute arbitrary SQL commands via the idcategory parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13652  CVE-2005-2446  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2369. Reason: This candidate is a duplicate of CVE-2005-2369. Notes: All CVE users should reference CVE-2005-2369 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050803)  None (candidate not yet proposed)    View

Page 19056 of 20943, showing 5 records out of 104715 total, starting on record 95276, ending on 95280

Actions